mirror of
https://github.com/greenart7c3/Amber.git
synced 2026-10-05 19:08:23 +00:00
80 lines
2.7 KiB
YAML
80 lines
2.7 KiB
YAML
name: Check Offline Build Permissions
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [master]
|
|
push:
|
|
branches: [master]
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
check-offline-permissions:
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 20
|
|
|
|
steps:
|
|
- uses: actions/checkout@v7
|
|
|
|
- name: Set up JDK 21
|
|
uses: actions/setup-java@v6
|
|
with:
|
|
distribution: 'temurin'
|
|
java-version: 21
|
|
|
|
- name: Cache Gradle
|
|
uses: actions/cache@v6
|
|
with:
|
|
path: |
|
|
~/.gradle/caches
|
|
~/.gradle/wrapper
|
|
key: ${{ runner.os }}-gradle-${{ hashFiles('**/*.gradle*', '**/gradle-wrapper.properties') }}
|
|
restore-keys: |
|
|
${{ runner.os }}-gradle-
|
|
|
|
- name: Create keystore.properties
|
|
run: touch keystore.properties
|
|
|
|
- name: Generate merged manifest for offline build
|
|
run: ./gradlew processOfflineDebugManifest --no-daemon
|
|
|
|
- name: Check for network permissions in offline merged manifest
|
|
run: |
|
|
MANIFEST=$(find app/build/intermediates/merged_manifests -name "AndroidManifest.xml" | grep -i offline | head -1)
|
|
if [ -z "$MANIFEST" ]; then
|
|
echo "ERROR: Could not find merged manifest for offline build"
|
|
exit 1
|
|
fi
|
|
echo "Checking: $MANIFEST"
|
|
FAILED=0
|
|
for PERMISSION in android.permission.INTERNET android.permission.CHANGE_NETWORK_STATE android.permission.ACCESS_NETWORK_STATE; do
|
|
if grep -q "$PERMISSION" "$MANIFEST"; then
|
|
echo ""
|
|
echo "ERROR: $PERMISSION found in offline build manifest!"
|
|
echo "The offline flavor must not include network permissions."
|
|
echo ""
|
|
echo "Offending lines:"
|
|
grep "$PERMISSION" "$MANIFEST"
|
|
FAILED=1
|
|
else
|
|
echo "OK: No $PERMISSION in offline build manifest"
|
|
fi
|
|
for COMPONENT in androidx.work.WorkManagerInitializer androidx.work.impl.background.systemjob.SystemJobService; do
|
|
if grep -q "$COMPONENT" "$MANIFEST"; then
|
|
echo ""
|
|
echo "ERROR: $COMPONENT found in offline build manifest!"
|
|
echo "WorkManager must never initialize in the offline flavor: it tracks"
|
|
echo "network-constrained work via ConnectivityManager, which crashes with"
|
|
echo "SecurityException because ACCESS_NETWORK_STATE is removed."
|
|
echo ""
|
|
echo "Offending lines:"
|
|
grep "$COMPONENT" "$MANIFEST"
|
|
FAILED=1
|
|
else
|
|
echo "OK: No $COMPONENT in offline build manifest"
|
|
fi
|
|
done
|
|
done
|
|
exit $FAILED
|